Impact
Dragonfly is an open source peer‑to‑peer file distribution system that, before the release of version 2.4.4‑rc.3, allows unauthenticated users to specify a PeerHost.Ip and PeerHost.DownPort via the v1 gRPC RegisterPeerTask or ReportPeerResult methods. The scheduler stores these values into resource.Host and later calls Peer.DownloadTinyFile() for a small TINY task. In that function the code constructs an HTTP GET request directly from the supplied address, performing no validation of the destination. This enables an attacker to cause the scheduler to send outbound HTTP requests to loopback, link‑local, or RFC1918 addresses, placing up to 128 bytes of the response payload into Task.DirectPiece for later retrieval. The vulnerability therefore provides read‑type SSRF (CWE‑918) rather than remote code execution. Attempts to target private ranges are not blocked because IsGlobalUnicast accepts RFC1918 addresses, though loopback and link‑local targets are prevented by remediation in the fixed release.
Affected Systems
Dragonfly OSS Scheduler, any version prior to 2.4.4‑rc.3. The vulnerability exists in the default scheduler configuration that accepts unauthenticated gRPC requests.
Risk and Exploitability
The CVSS score is 5.5, indicating a medium severity. The EPSS score of 0.00487 reflects a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to send a malicious RegisterPeerTask or ReportPeerResult request to an exposed scheduler endpoint, which then performs an outbound HTTP GET. Because the affected port range is 1024–65534, many internal services could be probed, but the payload size is limited to 128 bytes, restricting the amount of data returned.
OpenCVE Enrichment
Github GHSA